CVE-2024-38225: Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Published Sep 10, 2024
·Updated
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Affected Software
6 affected componentsFixes available
Microsoft Dynamics 365 Business Central=2023-release_wave_1
Microsoft Dynamics 365 Business Central=2023-release_wave_2
Microsoft Dynamics 365 Business Central=2024-release_wave_1
Microsoft Dynamics 365 Business Central 2023 Release Wave 2
Microsoft Dynamics 365 Business Central 2023 Release Wave 1
Microsoft Dynamics 365 Business Central 2024 Release Wave 1
Remediation
Event History
Sep 10, 2024
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38225?
CVE-2024-38225 has been assigned a severity rating of critical due to its potential to allow elevation of privileges in Microsoft Dynamics 365 Business Central.
2
How do I fix CVE-2024-38225?
To remediate CVE-2024-38225, you should apply the latest security patches provided by Microsoft for the affected versions of Dynamics 365 Business Central.
3
Which versions of Microsoft Dynamics 365 Business Central are affected by CVE-2024-38225?
CVE-2024-38225 affects Microsoft Dynamics 365 Business Central 2023 Release Wave 1, 2023 Release Wave 2, and 2024 Release Wave 1.
4
What type of vulnerability is CVE-2024-38225?
CVE-2024-38225 is classified as an elevation of privilege vulnerability.
5
Can CVE-2024-38225 be exploited remotely?
CVE-2024-38225 may be exploited remotely, allowing an attacker to gain elevated permissions within the affected application.